VYPR

Tivoli Business Service Manager

by IBM

CVEs (3)

  • CVE-2014-3031Aug 12, 2014
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 4.2.0 before 4.2.0.0 IF12 and 4.2.1 before 4.2.1.3 IF9 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

  • CVE-2008-0441Jan 25, 2008
    risk 0.00cvss epss 0.00

    IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive information.

  • CVE-2007-1940Apr 11, 2007
    risk 0.00cvss epss 0.00

    IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.